Nova Patents
US9787684B2

Networked access control system

Summary by NHIP

Three-Party Token Verification

The method controls network access by exchanging encrypted identifiers among a server, mobile device, and lock device. The mobile device generates a third data set containing a second identifier and a first data subset encrypted by a second cryptographic key before transmitting it to the server for verification.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Methods and systems for controlling a network access control system that includes a server encrypting a first identifier that can be related to a registered user and communicating the encrypted first identifier to the mobile device. The lock device receives, from the mobile device, a first data set that includes at least the encrypted first identifier. The lock device may encrypt the first data set to generate a second data set and communicates the encrypted second data set to the mobile device. The server receives a third data set that includes at least the encrypted second data set and a second identifier that can also be related to the registered user. The server extracts from the communicated third data set the first and second identifiers, and the extracted first and second identifiers are compared to verify that the second identifier is indeed related to the first identifier.

US9787684B2, drawing sheet 1
Sheet 1 of 5

Term

8.8 yearsleft in the term

Expires 10 July 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

25 claims: 3 independent, 22 dependent

  1. 1
    Broadest claimClaim Score 41, average(NHIP)A method for controlling a network access control system, the method comprising:receiving, by a mobile device and from a server, an application token, wherein the application token includes a first identifier associated with the mobile device and encrypted by a first cryptographic key;transmitting, by the mobile device and to a lock device, a first data set including the application token;receiving, by the mobile device and from the lock device, a second data set generated by the lock device based on the first data set and including a second identifier and a first data subset encrypted by a second cryptographic key, wherein the first data subset includes the first identifier and the application token, and wherein the second identifier is associated with at least one of the mobile device, the lock device, an application of the mobile device, or a registered user;generating, by the mobile device, a third data set based on the second data set and including a third identifier, wherein the third data set includes the second identifier, the third identifier, and the first data subset encrypted by the second cryptographic key;andtransmitting, by the mobile device, the third data set to the server for extraction of the first identifier and the second identifier from the third data set and verification that the first identifier is related to the second identifier.
  2. 13
    A plurality of non-transitory machine-readable storage media comprising a plurality of instructions stored thereon that, in response to execution by a mobile device, results in the mobile device:receiving, by the mobile device from a server, an application token, wherein the application token includes a first identifier associated with the mobile device and encrypted by a first cryptographic key;transmitting a first data set including the application token to a lock device;receiving, from the lock device, a second data set generated by the lock device based on the first data set and including a first data subset encrypted by a second cryptographic key and a second identifier associated with at least one of the mobile device, the lock device, an application of the mobile device, or a registered user, the first data subset including the first identifier and the application token;generating a third data set based on the second data set and including the second identifier, a third identifier, and the first data subset encrypted by the second cryptographic key;andtransmitting the third data set to the server for extraction of the first identifier and the second identifier from the third data set and verification that the first identifier is related to the second identifier.
  3. 19
    A network access control system, comprising:at least one processing device;andat least one memory comprising a plurality of instructions stored thereon that, in response to execution by the at least one processing device, causes the network access control system to:receive, by a mobile device and from a server, an application token, wherein the application token includes a first identifier associated with the mobile device and encrypted by a first cryptographic key;transmit, by the mobile device and to a lock device, a first data set including the application token;receive, by the mobile device and from the lock device, a second data set generated by the lock device based on the first data set, wherein the second data set includes a first data subset encrypted by a second cryptographic key and a second identifier, wherein the first data subset includes the first identifier and the application token, and wherein the second identifier is associated with at least one of the mobile device, the lock device, an application of the mobile device, or a registered user;generate, by the mobile device, a third data set based on the second data set, wherein the third data set includes the second identifier, a third identifier, and the first data subset encrypted by the second cryptographic key;andtransmit, by the mobile device, the third data set to the server for extraction of the first identifier and the second identifier from the third data set and verification that the first identifier is related to the second identifier.